CVE-2025-2781: WatchGuard Mobile VPN With SSL Client

Medium severity, CVSS 6.3. EPSS: 0.1% chance of exploitation in the next 30 days.

The WatchGuard Mobile VPN with SSL Client on Windows does not properly configure directory permissions when installed in a non-default directory. This could allow an authenticated local attacker to escalate to SYSTEM privileges on a vulnerable system.

Affected products

  • WatchGuard Mobile VPN With SSL Client: from 11.0, before 12.11.2 (fixed in 12.11.2)

Published 2025-03-28. Last modified 2026-08-08.